AI Weekly Malaysia

Back to items Summaries

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

ID
21808
Status
summarized
Published
06 Sep 2026, 12:05 AM
Fetched
06 Sep 2026, 1:09 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
06 Sep 2026, 1:10 AM
Tags
Audience
developersvibe_coders

What happened

Broadcom patched two VMware Workstation and Fusion vulnerabilities (CVE-2026-59346, CVSS 9.3; CVE-2026-59347, CVSS 8.1) that let a local admin inside a VM execute code on the host machine. Both affect versions 25H2 and 26H1, with no workarounds available; fixes shipped in VMware Workstation and Fusion 26H1u1.

Why it matters

If you run VMware Workstation or Fusion for local dev or testing on versions 25H2 or 26H1, update to 26H1u1 now — a compromised VM can escape to your host. This matters most for anyone running untrusted code or multi-tenant VMs locally; if your VMs are single-user and trusted, the risk is lower since exploitation requires existing local admin inside the VM.

Discussion angle

How many of us still run local desktop hypervisors (VMware Workstation/Fusion) versus containers or cloud VMs, and does VM-to-host escape change that calculus for anyone running untrusted code locally?

Top